zc-bug-fix
Warn
Audited by Socket on Apr 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s capabilities broadly match its bug-fix purpose, but it concentrates sensitive ZenTao and GitLab credentials in a local config and forwards them to unreviewed shell scripts that perform networked state changes. No obvious malicious exfiltration or deceptive installer is present, yet the credential handling, private/self-hosted endpoints, and ability to push code and update trackers make the overall risk medium.
Confidence: 88%Severity: 56%
Audit Metadata